Cloud repatriation — exit public cloud without breaking the application

Open-source Cozystack (a CNCF project we create and maintain) Ænix Platform, the supported commercial distribution Aenix builds, operates and migrates it.

Cloud repatriation is the practice of moving selected workloads out of public cloud (AWS, Azure, GCP) into private cloud, hybrid, or on-premises environments, typically to cut steady-state cost, satisfy data-sovereignty and regulatory pressure (DORA, NIS2, GDPR), or control AI and inference economics. Aenix runs a structured repatriation engagement, delivered as part of its Platform Readiness Assessment, that produces an honest TCO model, a per-workload “repatriate now / later / stay” ranking, a destination architecture, and a cutover sequence. Aenix is the company behind Cozystack, an Apache 2.0 CNCF project that unifies VMs and containers on one Kubernetes API and is the platform Aenix typically recommends as a repatriation destination. The engagement is delivered by engineers with no hyperscaler commercial bias.

Quick facts

  • What it is A structured engagement that moves selected workloads from public cloud to private cloud, hybrid, or on-prem without breaking the application.
  • License Apache 2.0 (no per-CPU / per-core licensing)
  • Status Cozystack is a CNCF project (Sandbox since 2025-02-28; Incubating expected late summer 2026)
  • Engagement length 14-day (focused TCO + repatriation) or 28-day (full repatriation program), fixed-price, single invoice
  • Who it is for Organizations with seven-figure cloud bills, predictable steady-state workloads, sovereignty exposure, or AI/ML egress and inference costs, plus an internal platform-engineering function
  • Deliverables Honest TCO model, per-workload repatriation ranking, destination architecture, cutover sequencing, and a Phase 2 implementation roadmap
  • Destination platform Cozystack — KubeVirt for VMs and containers on one Kubernetes API, Cilium (eBPF) networking, LINSTOR/DRBD storage, Tenant CRD multi-tenancy

The Broadcom Private Cloud Outlook 2025 found 69% of organizations are evaluating cloud repatriation, and 53% now prioritize private cloud for new workloads. The reasons vary — runaway cost, regulator pressure, AI data residency, predictable performance — but the architectural work is the same: identify the right workloads to move, run the move without breaking the application, and end up with a platform you can actually operate.

Ænix runs the technical engagement that turns “we need to leave AWS / Azure / GCP” from a board statement into a working plan with workloads ranked, costs modelled, and a destination architecture that won’t reinvent the public cloud the wrong way.

Pairs with the Ænix platform that matches the destination: Private Cloud Platform if you run the capacity for your own business units, Public Cloud Platform if you sell it on, AI Platform if the repatriated workloads are GPU-bound. Free Cloud Repatriation TCO Worksheet →.

No hyperscaler bias · Honest TCO modelling · Engineers, not consultants · Apache 2.0 platform

Who repatriation actually fits

Repatriation is not for everyone. The teams that benefit most share a common profile:

  • Heavy public-cloud bills — annual spend in the seven figures, and the renewal trajectory is steeper than revenue.
  • Predictable, steady-state workloads — not the elastic spike workloads hyperscalers were designed for.
  • Sensitive data with sovereignty exposure — financial, healthcare, public-sector, or regulated-industry data that increasingly attracts regulatory pressure.
  • AI / ML workloads with egress and inference cost concerns — model serving and training where hyperscaler economics break down at scale.
  • An internal platform-engineering function (or one being stood up) — repatriation requires somebody to run the destination platform afterwards.

If your situation matches at least three of those, repatriation deserves a structured look. If you have a small IT team running a handful of services, the answer is almost always “stay in public cloud and tune your spend.”


Four reasons teams repatriate in 2026

1. Predictable cost on steady-state workloads Hyperscaler economics favor elasticity. For workloads that run 24/7 at predictable utilization, the unit economics on-prem or in private cloud are routinely 30-60% better once egress, idle resources, and underutilized commitments are counted honestly.

2. Regulatory and sovereignty pressure DORA (in force January 2025), NIS2, GDPR, sectoral data-residency rules, and procurement-led sovereignty mandates (EU member states, Kazakhstan, others) increasingly force critical workloads into an environment the organization controls itself.

3. AI and analytics on sensitive data GenAI, inference, and analytics workloads against regulated data classes face two-front pressure: model providers’ data-handling terms aren’t acceptable, and inference egress costs make hyperscaler economics unworkable at scale.

4. Operational and architectural control Hyperscaler-proprietary services lock the architecture into one vendor’s roadmap. Repatriation gives the platform team back the ability to choose, evolve, and audit the underlying components.


Where most repatriation projects go wrong

The TCO model is wishful, not honest Hardware cost is easy. Network, datacenter, storage tiering, observability, identity, backup, DR, ongoing platform-engineering capacity — usually missing or underestimated. The result: repatriation looks cheaper than it is, then disappoints the CFO 18 months in.

The destination architecture is left for later Workloads get moved to “an on-prem cluster” without a real platform underneath. The team rebuilds, in worse form, what hyperscalers spent a decade engineering. Self-service breaks. Velocity drops. Repatriation gets blamed.

Data gravity is treated as a checkbox “Move the database last” — without a real plan for how 50 TB of production data crosses the network, what the cutover window looks like, how the rollback path works, and where backups live during the move.

The exit is full-scope when selective is the right answer Most repatriations are not all-or-nothing. The right outcome is usually 30-60% of workloads on-prem (the steady-state, regulated, or expensive ones), 40-70% staying in public cloud (the elastic, latency-sensitive, or hyperscaler-only ones). Treating repatriation as a binary decision destroys the economic case.

These failure modes are independent of cloud provider, vendor, or destination platform — they’re what happens when repatriation is run as a spreadsheet exercise instead of a platform-engineering program.


How Ænix helps

Public cloud
AWSAzureGCP
assessed by
Platform Readiness Assessment
Honest TCO modelWorkload rankingDestination architecture
repatriate now / later / stay
Cozystack private cloud
VMsContainersOne Kubernetes API
on
Bare metal you own
Private cloud, hybrid, or on-prem

The repatriation engagement runs as part of our Platform Readiness Assessment, with the cost-and-cloud-spend workstream as primary focus. The 14- or 28-day engagement produces:

  • Honest TCO model — current public cloud spend (incl. egress, commitment underutilization, hidden costs) vs. realistic destination cost on private cloud or hybrid.
  • Workload repatriation ranking — every workload classified as “repatriate now / repatriate later / stay in cloud,” ranked by ROI and risk.
  • Destination architecture — what the platform looks like that workloads land on, including compute, storage, network, identity, observability, DR, and the platform-engineering function that operates it.
  • Cutover sequencing — repatriation cohorts that respect commitment expirations and minimize cross-environment data movement.
  • Phase 2 implementation roadmap — what an Ænix-delivered Phase 2 would do, in what sequence, with effort estimates.

Delivered by Ænix engineers who have built and operated production platforms for service providers, banks, and AI operators across the EU and Central Asia. The report’s bias is toward what we can stand behind technically.


Why Ænix specifically

  • No hyperscaler bias. Repatriation advisory work from Big-4 consultancies is shaped by their hyperscaler partnerships. Our recommendations are not commercially tied to AWS, Azure, GCP, or any single provider — we say “stay in public cloud” when that’s the answer, and we say “fully on-prem” when that’s the answer.
  • Engineers, not consultants. The engineers who run the repatriation engagement build the production platforms afterwards. The implementation effort estimates in the report are calibrated against work we have actually shipped — not against industry benchmarks.
  • Open-source destination platform. We are the company behind Cozystack — an open-source Kubernetes-native cloud platform (CNCF Project, Kubernetes Certified Distribution). Where Cozystack fits the destination architecture better than the alternative, the report explains why with named architectural attributes. Where it doesn’t, we say so.

Ready to scope your build? Book a call →

What the engagement looks like

Day 0 is a free 30-minute discovery call that fixes the scope. Days 1-13 (or 1-27) run four parallel workstreams with the cost-and-cloud-spend workstream emphasized, on daily async updates and three sponsor checkpoints. Day 14 (or 28) is a 60-90 minute executive readout against the written report — workload ranking, TCO model, destination architecture, cutover sequencing and Phase 2 roadmap. Full day-by-day methodology: Platform Readiness Assessment.


Repatriation projects we’ve supported

We have run cloud-repatriation engagements for service providers, financial-services organizations, telecom operators, and AI/GPU platforms across the EU, DACH, and Central Asia. Workloads moved have ranged from steady-state production databases to AI inference clusters; outcomes have ranged from full on-prem to selective hybrid.


Pricing and engagement scope

The repatriation-emphasized engagement runs as a Platform Readiness Assessment.

14-day (focused TCO + repatriation)

TCO modelling depth, workload portfolio ranking, destination architecture options, cutover sequencing for top-priority workloads. On request

28-day (full repatriation program)

Adds vendor shortlisting (compute / storage / network / observability), proof-of-concept scoping for 1-2 priority workloads, multi-BU stakeholder interviews, complete Phase 2 implementation roadmap. On request

Fixed-price. Single invoice. Mutual NDA at kickoff. Phase 2 implementation cost: assessment fee credited subject to scope.

We accept RFI / RFP through standard procurement channels in EU member states and Kazakhstan.



Start with a 30-minute discovery call

We confirm fit, identify the workloads worth moving, and name the 14-day or 28-day variant.

Or read more:


Ænix is the company behind Cozystack — a CNCF Project, Kubernetes Certified Distribution, OpenSSF Best Practices. We run cloud-repatriation engagements and platform engineering programs for service providers, banks, telecom, and AI operators across the EU, DACH, and Central Asia.

Frequently asked questions

Is cloud repatriation the same as going fully on-prem?

No. Repatriation usually means moving a subset of workloads — typically 30-60%, the steady-state, regulated, or expensive ones — to private cloud, hybrid, or on-prem, while elastic and latency-sensitive workloads stay in public cloud. Treating it as all-or-nothing usually destroys the economic case.

How long does a cloud repatriation take?

The Aenix assessment is 14 or 28 days. Phase 2 implementation depends on estate size: roughly 6-12 months for a 100-VM estate and 12-24 months for a 1000-VM estate. The economic case typically clarifies after 9-12 months as cloud commitments lapse.

Will Aenix just recommend Cozystack at the end?

Only where it fits. Where Cozystack suits the destination architecture better than the alternative, the report explains why with named architectural attributes. Where a different stack fits — hyperscaler with better controls, OpenShift, or vanilla Kubernetes on commodity hardware — Aenix says so. There is no hyperscaler commercial bias.

What does the repatriation destination platform cost?

Cozystack itself is Apache 2.0 with no per-CPU or per-core licensing. The productized Ænix Platform is priced two ways: Public Cloud Platform and Cozystack with Ænix enterprise support run off a published support-tier price list from $1,250/month per 10 nodes; Private Cloud Platform and AI Platform programmes are quoted per RFP after scoping. See the pricing page.

What if our public cloud reserved commitments lock us in?

The cutover sequencing plan respects commitment expiration ladders. Repatriation cadence is aligned with AWS Reserved Instances, Azure RI, and Savings Plan expirations rather than fighting them, so workloads move as commitments lapse.

What if our team cannot operate a private cloud platform afterwards?

Two paths are scoped during the assessment: Aenix runs the platform under a managed-services arrangement, or Aenix builds your platform team’s capacity through a structured platform-engineering engagement.

Ready to talk?

Book a 30-minute discovery call — no commitment. We confirm fit, the right platform, and the next steps.